Custom headers on cpsrvd

Operating System & Version
CentOS v7.9.2009
cPanel & WHM Version
cPanel & WHM v104.0.7

lboxmtl

Registered
Jul 26, 2022
1
0
1
canada
cPanel Access Level
Root Administrator
My Cpanel/whm powered server falls under a larger government policy which has updated its security policies and its now performing weekly audits / scans.
In order to be compliant, I need to add a custom response header to all responses returned by cpsrvd
(specifically: Content-Security-Policy: frame-ancestors, although it's possible others will be added in the future)

I am not finding where to add a custom header; googling for the subject mostly leads to a binary option to add a preset X-Frame-Options in WHM tweak settings.
Does anyone know how do I add/modify a custom header to cpsrvd pages?

There's a somewhat related post here:

where the user is looking to modify the X-Frame-Options: SAMEORIGIN to ALLOWALL and thread ends with no solution.



will i need to insert a proxy layer on top of my server for this?


if anyone has any info, would be appreciated!
 
Last edited by a moderator:

cPRex

Jurassic Moderator
Staff member
Oct 19, 2014
14,253
2,219
363
cPanel Access Level
Root Administrator
Hey there! I don't have a way to create custom headers for the cpsrvd service at this time. The best way to get this added would be to use the link in my signature to submit a feature request, and then our developers can review that. I know that doesn't solve your current need, but that is the best option to get a supported method to make this change added to the product.